Latest
FAQ: The AmService in IG routes
The purpose of this FAQ is to provide answers to commonly asked questions regarding the AmService in IG routes.
FAQ: IG in Standalone Mode
The purpose of this FAQ is to provide answers to commonly asked questions regarding IG in standalone mode. This is a non-Web container dependent release of IG, which is delivered as a standalone Java® executable.
Do ForgeRock products run on AWS?
AWS stands for Amazon Web Services and encompasses a range of cloud-based services provided by Amazon. ForgeRock products work well with many AWS offerings. Additionally, ForgeRock has also partnered with AWS to make it even easier for companies to control access to AWS Resources.
What operating systems are ForgeRock products supported on?
The purpose of this article is to provide a summary of the currently supported operating systems for the latest ForgeRock products: AM 7.1, DS 7.1, IDM 7.1 and IG 7.1.
Does the ForgeRock Identity Platform include an audit logging service?
The ForgeRock Identity Platform includes a REST-based Audit Logging Service that captures all auditing events critical for system security, troubleshooting, usage analytics and regulatory compliance.
Do ForgeRock products run on VMware?
The short answer is yes they do. ForgeRock products can run very successfully on VMware providing you configure your VMware environment correctly.
Is the ForgeRock Identity Platform FIPS 140-2 compliant?
ForgeRock can make use of a FIPS 140-2 certified cryptographic module through a standard PKCS#11 interface.
Does the ForgeRock solution offer single and same sign-on (SSO) capabilities?
The ForgeRock solution includes a wide range of integration patterns and platform components that enable single and same sign-on (SSO) for both modern and legacy applications.
ForgeRock Production Event Guidance/Checklist
The purpose of this article is to provide general best practices on how to plan and prepare for major events with ForgeRock support. Examples of a major event are: going live with a ForgeRock product, production upgrades, major releases and so on.
Could not transfer artifact org.forgerock.commons:commons-bom:pom error when building ForgeRock Identity Platform 6.5.x
The purpose of this article is to provide assistance if building AM, DS, IDM or IG from source fails with a "Non-resolvable import POM: Could not transfer artifact org.forgerock.commons:commons-bom:pom" error.
Books
Product Q&As - ForgeRock Identity Platform
This book provides answers to questions when evaluating the ForgeRock Identity Platform and its components (AM, DS, IDM and IG). It assumes that the platform is deployed on-premises or in a private or public cloud rather than ForgeRock-hosted in Identity Cloud.
Platform compatibility
This book provides information on compatibility between ForgeRock products (AM, DS, IDM and IG).
Performance tuning and monitoring ForgeRock products
This book provides information on performance tuning and monitoring ForgeRock products (AM, DS, IDM and IG).
Security Advisories
This book provides security advisories for ForgeRock products (AM, DS, IDM and IG).
SAML federation in IG
This book provides information on SAML federation in IG and includes help on configuring federation and debug logging.
Troubleshooting IG
This book provides information on troubleshooting various issues in IG including collecting useful troubleshooting information such as logs, heap dumps and stack traces.
Installing and configuring IG
This book provides information on installing and configuring IG including frequently asked questions.
Security Advisories
Spring Framework Security Advisory #202203
The purpose of this advisory is to inform our customers that, based on current information, ForgeRock products (Identity Cloud, AM, DS, IDM, IG, Agents and Autonomous Identity) are NOT vulnerable to the Spring Framework vulnerabilities: Data Binding Rules CVE-2022-22968, RCE (Remote Code Execution) CVE-2022-22965 (Spring4shell), RCE CVE-2022-22963 and DoS (Denial of Service) CVE-2022-22950.
Java JDK Security Advisory #202109
ForgeRock are aware of a serious vulnerability in the implementation of certain cryptographic operations in Java® JDK versions 15 and later: CVE-2022-21449. This vulnerability affects Oracle® Java and OpenJDK, including other JDKs derived from OpenJDK. You should follow the advice in this advisory to secure your deployments at the earliest opportunity.
Log4j Security Advisory #202111
The purpose of this advisory is to provide information on whether ForgeRock products (Identity Cloud, AM, DS, IDM, IG, Agents and Autonomous Identity) are vulnerable to recent Log4j 2 vulnerabilities: RCE (Remote Code Execution) CVE-2021-44228, DoS (Denial of Service) CVE-2021-45046, DoS CVE-2021-45105 and ACE (Arbitrary Code Execution) CVE-2021-44832. These vulnerabilities allow an attacker to remotely execute code in certain circumstances.